CVE-2017-8601
HIGH EXPLOITED IN THE WILDMicrosoft Edge - Remote Code Execution via JavaScript Engine Memory Corruption
Title source: llmExploitation Summary
CVE-2017-8601 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Google Security Research.
AI-analyzed exploit summary This PoC exploits a type confusion vulnerability in Microsoft Edge's JavaScript engine by manipulating array and typed array objects. The exploit triggers a memory corruption issue by passing a crafted object to the 'func' function, leading to potential remote code execution.
Description
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8610, CVE-2017-8618, CVE-2017-8619, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, CVE-2017-8598 and CVE-2017-8609.
Exploits (1)
This PoC exploits a type confusion vulnerability in Microsoft Edge's JavaScript engine by manipulating array and typed array objects. The exploit triggers a memory corruption issue by passing a crafted object to the 'func' function, leading to potential remote code execution.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H